Getting Data In

Would I be able to rename a "Source Type" after the data got already indexed into Splunk?

clyde772
Communicator

Would I be able to rename a "Source Type" after the data got already indexed into Splunk?

Can I rename a type of pattern data into another "Souce Type"

or

I have to delete the type of source and reindex?

Tags (1)

jrodman
Splunk Employee
Splunk Employee

In addition, you can make splunk treat sourcetype A as if it were sourcetype B for search purposes.

http://www.splunk.com/base/Documentation/4.1.2/Admin/Renamesourcetypes

This only allows you to cause ALL of sourcetype A to now be considered B.

Simeon
Splunk Employee
Splunk Employee

You Cannot rename a Source Type after it has already been indexed. However, you can use tags or aliases to alter the way you identify those events:

http://www.splunk.com/base/Documentation/latest/Knowledge/Abouttagsandaliases

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...